- › Britain's criminal records office was breached three times between July 2021 and June 2023, and nobody noticed for nearly two years.
- › Trend Micro quarantined four separate attempts to install Mimikatz during the intrusion. The tool detected it and acted every time.
- › ACRO told the regulator it could not establish what business process existed for handling those alerts.
- › The public portal ran the same version of its content management system since September 2019, and ACRO, its managed service provider, and its web developer could not identify who was responsible for patching it.
- › The ICO found that acting on the alerts could have prevented further malicious activity, and issued a reprimand with no fine.
Somewhere in your organization there is a screen with a number on it, and the number has been red for a while.
Maybe it is an email folder. Maybe it is a console somebody logs into when there is time. Whoever set it up left, or changed roles, or is still there and now owns four other things. The alerts still arrive. They have arrived every week for two years and nothing has ever come of any of them, which is the exact evidence a reasonable person uses to decide the queue is not urgent.
That is the shape of what happened to ACRO, the unit that manages Britain’s criminal records on the Police National Computer.
What the Tool Did Right
Between July 2021 and June 2023 there were three separate intrusions through a public-facing customer portal. In the most serious, the attackers held persistent access for roughly seven months, from August 2022 to March 2023.
During that window, Trend Micro’s software detected and quarantined four separate attempts to install Mimikatz. Mimikatz is a credential-harvesting tool. It is not ambiguous. There is no benign reason for it to appear on a system holding criminal records, and the security product identified it correctly and stopped it, four times.
The Information Commissioner’s Office was direct about what that means: if the alerts had been acted upon, further malicious activity could have been prevented.
I want to sit on that a moment, because the reflex when reading it is to look for the analyst who ignored four alerts.
There was no analyst. ACRO told the regulator it could not establish what business process existed for handling such alerts. Not that the process failed. That nobody could determine one had ever existed.
Nobody Ignored Anything
This is the part I care about, and it is the part that gets written up wrong almost every time.
An investigation that concludes with “the alerts were ignored” has found a person to be disappointed in and has stopped looking. It feels like an answer. It changes nothing, because the next organization will buy the same tool, generate the same alerts, and route them to the same nowhere.
Ask instead who was supposed to read them. Then ask how that person would have known the alert was theirs, what they were authorized to do about it at 4pm on a Thursday, who they escalated to, and what happened the last time somebody escalated. In a lot of organizations those questions have no answers, and the absence is invisible because the tool is installed and the dashboard is green and the auditor saw a screenshot.
An alert that reaches nobody is just logging with better marketing.
And notice what the tool’s success actually produced here. It quarantined the credential stealer, so nothing broke. No outage, no ransom note, no visible consequence. The system that was supposed to raise the alarm instead absorbed the blow silently four times while the intruders kept working. A control that half-works can be worse than one that fails loudly, because the loud failure gets somebody’s attention.
The Second Failure Is the One I See Most
The portal ran the same version of its content management system from September 2019 through the breaches, with multiple publicly documented vulnerabilities in it the whole time.
Here is why nobody patched it. ACRO, its managed service provider, and its web development supplier could not identify who bore responsibility for applying security patches.
Three organizations. One system. No owner.
I have watched this play out in enough assessments to know it is almost never a fight. Nobody refused the work. Each party had a reasonable read of scope in which patching was somebody else’s, and none of them had a reason to test that read until an investigator asked. The gap did not appear when the contracts were signed. It appeared because nothing ever forced the question.
That is a procurement artifact, and it is worth naming as one. The technical fix is trivial and the reason it did not happen is contractual.
What It Cost
Roughly 11,000 people had sensitive data staged for exfiltration during the seven-month access period. ACRO notified more than 84,000 people who had submitted applications during the at-risk window, as a precaution.
Among them were domestic violence victims.
ACRO holds criminal records and processes background checks, which means it holds the addresses and identities of people whose safety depends on those staying private. That is the same category we wrote about when the Metropolitan Police served a stalking suspect his victim’s new address, in your data handling is a physical security control. Different failure, same people standing underneath it.
The organization disclosed in April 2023, after a newspaper contacted them. Their initial public position was that the website was down for maintenance.
The ICO issued a reprimand and no financial penalty.
What to Actually Check
None of this requires new tooling. Every one of these is a question about whether the thing you already bought reaches a human being.
Follow one real alert end to end
Pick an actual alert your endpoint tool generated this month and trace it. Where did it go, who opened it, what did they do, and how long did it take. Not the documented process. What happened to that specific alert. Most people discover the trail stops somewhere they did not expect.
Name the person, not the team
“Security operations reviews the alerts” is how a queue ends up unread. A named individual with a named backup, written down, is the difference between a responsibility and an assumption. Teams do not read things. People do.
Ask what happened the last time someone escalated
This tells you more about your culture than any survey. If the last person to escalate a false positive got a comment about wasting time, you have taught everyone the cost of being wrong and none of them will escalate again. If nobody can remember an escalation at all, that is its own answer.
Put a name on patching in the contract, not the meeting
For every system with a managed service provider or an outside developer involved, find the sentence in the agreement that says who patches it. If there is no sentence, that is the finding, and it is cheaper to fix now than during an investigation where three parties point at each other.
Test the silence
A control that has never fired is indistinguishable from a control that is broken. Generate a benign detection on purpose and see whether anyone notices. If nothing happens, you have learned something enormously valuable for the price of an afternoon.
Count how many queues you have
Most organizations have more alert destinations than they realize: the endpoint console, the firewall email, the cloud provider’s notifications, the alerts the managed service provider sees but does not forward. Every one is a place something can arrive and stop. Write the list.
The Part Worth Keeping
The security product did its job. It detected a credential-harvesting tool four separate times and stopped it every time. Somebody chose that product, deployed it, and kept it running, and it worked exactly as designed.
Then the alert went into a room with nobody in it, for two years.
Go find your own room.
Want to know whether the alerts your tools generate actually reach a person who can act? Take our free Human Attack Surface Score assessment, or contact us for a full risk assessment.
With a dual background in I/O Psychology (PhD Candidate) and Business Management (MBA), Marie bridges the gap between clinical rigor and operational strategy. She oversees B2B relations, compliance, and the 'business' of risk management.
View Author Page →